Security Digest: October 9, 2026 - 64 Critical Vulnerabilities
Today’s advisory list is dominated by critical remote-code-execution, privilege-escalation, and authentication-bypass flaws across Microsoft cloud services, FalkorDB, WordPress plugins, and security-sensitive infrastructure products. The most urgent exposure is any internet-facing or externally reachable service that is unpatched, especially Microsoft Azure/App Service, Microsoft Dataverse/Bookings/Partner Center, FalkorDB with Bolt enabled, and vulnerable WordPress deployments.
· 28 min read
Executive Summary
Today’s advisory list is dominated by critical remote-code-execution, privilege-escalation, and authentication-bypass flaws across Microsoft cloud services, FalkorDB, WordPress plugins, and security-sensitive infrastructure products. The most urgent exposure is any internet-facing or externally reachable service that is unpatched, especially Microsoft Azure/App Service, Microsoft Dataverse/Bookings/Partner Center, FalkorDB with Bolt enabled, and vulnerable WordPress deployments.
Act now: patch or disable exposed services first, then hunt for signs of exploitation, web shells, unexpected admin access, and anomalous authentication or database activity. If you cannot patch immediately, isolate the affected service, restrict network access, and rotate credentials or tokens that may have been exposed.
Critical Vulnerabilities
- CVE-2026-96207: Microsoft Partner Center certificate validation flaw
- Impact: Unauthorized network attacker can elevate privileges.
- Affected Systems: Microsoft Partner Center.
- Immediate Action: Apply Microsoft’s fix as soon as available; restrict access to trusted admin networks until then.
- Mitigation: Enforce least privilege and review Partner Center admin access.
- CVE-2026-94503: PX-lab Zombify dangerous file upload
- Impact: Web shell upload and full server compromise.
- Affected Systems: Zombify through 1.7.7.
- Immediate Action: Remove public upload paths or take the plugin offline until patched.
- Mitigation: Upgrade beyond 1.7.7 and scan for uploaded PHP files.
- CVE-2026-94510: Microsoft Bookings authorization bypass
- Impact: Privilege escalation over the network.
- Affected Systems: Microsoft Bookings.
- Immediate Action: Patch immediately and review Bookings permissions.
- Mitigation: Limit who can create or modify booking resources.
- CVE-2026-88131: Microsoft Dataverse deserialization RCE
- Impact: Remote code execution.
- Affected Systems: Microsoft Dataverse.
- Immediate Action: Apply vendor update and monitor for suspicious payload handling.
- Mitigation: Restrict access and inspect logs for anomalous requests.
- CVE-2026-5759: FalkorDB RDB decoder double free
- Impact: Denial of service or arbitrary code execution.
- Affected Systems: FalkorDB before 4.18.1.
- Immediate Action: Upgrade immediately; block untrusted Redis replication access.
- Mitigation: Require authentication and isolate replication endpoints.
- CVE-2026-107908: FalkorDB Bolt heap write
- Impact: DoS and possible RCE.
- Affected Systems: FalkorDB before 4.20.0 with Bolt enabled.
- Immediate Action: Disable Bolt if not required; patch now.
- Mitigation: Keep BOLT_PORT closed to untrusted networks.
- CVE-2026-77900: Azure App Service missing authentication
- Impact: Remote code execution.
- Affected Systems: Azure App Service.
- Immediate Action: Treat as emergency cloud patching; review exposed app endpoints.
- Mitigation: Restrict inbound access and verify platform updates.
- CVE-2026-69435: Azure SRE Agent authorization flaw
- Impact: Privilege escalation.
- Affected Systems: Azure SRE Agent.
- Immediate Action: Patch and audit service-agent permissions.
- Mitigation: Remove unnecessary operator roles.
- CVE-2026-93947: Traveler blind SQL injection
- Impact: Database compromise, data theft.
- Affected Systems: Traveler through 3.2.9.
- Immediate Action: Update plugin and review database exposure.
- Mitigation: Use prepared statements and WAF rules.
- CVE-2026-96327: WPLMS blind SQL injection
- Impact: Database extraction and tampering.
- Affected Systems: WPLMS before 1.9.9.8.2.
- Immediate Action: Patch immediately.
- Mitigation: Restrict admin access and inspect SQL logs.
- CVE-2026-96809: EduAdmin Booking blind SQL injection
- Impact: Data exposure and possible account takeover.
- Affected Systems: EduAdmin Booking before 6.0.0.
- Immediate Action: Upgrade now.
- Mitigation: Add query sanitization controls.
- CVE-2026-96331: Ajax Search Pro blind SQL injection
- Impact: Database compromise.
- Affected Systems: Ajax Search Pro through 4.29.1.
- Immediate Action: Patch and watch for abnormal search queries.
- Mitigation: Limit database privileges.
- CVE-2026-107935: gvproxy path traversal file deletion
- Impact: Arbitrary host file deletion.
- Affected Systems: gvisor-tap-vsock gvproxy.
- Immediate Action: Restrict the exposed endpoint immediately.
- Mitigation: Upgrade and validate caller-supplied paths.
- CVE-2026-96328: JNews - Pay Writer blind SQL injection
- Impact: Database compromise.
- Affected Systems: JNews - Pay Writer through 12.0.1.
- Immediate Action: Patch and review exposed forms.
- Mitigation: Use WAF and least-privilege DB accounts.
- CVE-2026-96330: tagDiv Opt-In Builder blind SQL injection
- Impact: Database extraction.
- Affected Systems: td-subscription through 1.7.6.
- Immediate Action: Upgrade immediately.
- Mitigation: Validate all subscription inputs.
- CVE-2026-7826: FalkorDB heap out-of-bounds read
- Impact: DoS and possible heap disclosure.
- Affected Systems: FalkorDB before 4.18.4.
- Immediate Action: Patch and restrict replication commands.
- Mitigation: Require authentication on Redis-facing services.
- CVE-2026-107909: FalkorDB Bolt WebSocket write
- Impact: DoS and possible heap corruption.
- Affected Systems: FalkorDB before 4.20.0 with Bolt enabled.
- Immediate Action: Disable Bolt unless strictly needed.
- Mitigation: Patch and firewall the Bolt port.
- CVE-2026-106155: Telerik Report Server stored XSS
- Impact: Script execution in another user’s session, including admin.
- Affected Systems: Telerik Report Server prior to 12.2.26.1007.
- Immediate Action: Upgrade and review report content from untrusted authors.
- Mitigation: Restrict report authoring privileges.
- CVE-2026-19569: Zephyr kernel object allocation wraparound
- Impact: Kernel memory corruption and potential sandbox escape.
- Affected Systems: Zephyr with CONFIG_USERSPACE and CONFIG_DYNAMIC_OBJECTS.
- Immediate Action: Patch kernels in embedded fleets urgently.
- Mitigation: Disable unneeded dynamic object paths where possible.
- CVE-2026-19570: Zephyr Bluetooth broadcast sink overflow
- Impact: Remote memory corruption via radio traffic.
- Affected Systems: Zephyr broadcast sink builds with periodic advertising sync.
- Immediate Action: Patch and reduce exposure to untrusted BLE sources.
- Mitigation: Disable broadcast sink features if unused.
- CVE-2026-96671: Featured Image from URL CSRF
- Impact: Unauthorized actions in WordPress admin flows.
- Affected Systems: featured-image-from-url through 6.0.7.
- Immediate Action: Update and enforce CSRF protections.
- Mitigation: Limit editor/admin roles.
- CVE-2026-83943: Azure API Center information disclosure
- Impact: Sensitive data exposure.
- Affected Systems: Azure API Center.
- Immediate Action: Review access and apply vendor guidance.
- Mitigation: Tighten network and identity controls.
- CVE-2026-95599: Taskbuilder blind SQL injection
- Impact: Database compromise.
- Affected Systems: Taskbuilder through 6.0.5.
- Immediate Action: Patch and monitor DB queries.
- Mitigation: Use parameterized queries.
- CVE-2026-94663: ProfileGrid blind SQL injection
- Impact: Data theft and tampering.
- Affected Systems: ProfileGrid through 6.0.0.2.
- Immediate Action: Upgrade immediately.
- Mitigation: Restrict plugin access paths.
- CVE-2026-95610: UpSolution Core blind SQL injection
- Impact: Database compromise.
- Affected Systems: UpSolution Core through 9.3.
- Immediate Action: Patch now.
- Mitigation: Review all forms and endpoints.
- CVE-2026-95607: WPLMS blind SQL injection
- Impact: Database compromise.
- Affected Systems: WPLMS through 4.973.
- Immediate Action: Upgrade.
- Mitigation: Validate inputs and monitor SQL errors.
- CVE-2026-96329: tagDiv Opt-In Builder blind SQL injection
- Impact: Database compromise.
- Affected Systems: td-subscription through 1.7.6.
- Immediate Action: Patch and test forms.
- Mitigation: Apply WAF filtering.
- CVE-2026-7827: FalkorDB stack overflow in RDB entity loader
- Impact: DoS and possible RCE.
- Affected Systems: FalkorDB before 4.18.4.
- Immediate Action: Upgrade and block unauthenticated replication access.
- Mitigation: Enforce authentication and segmentation.
- CVE-2026-107910: FalkorDB authentication bypass via Bolt
- Impact: Unauthorized graph query execution.
- Affected Systems: FalkorDB before 4.20.0 with Bolt enabled.
- Immediate Action: Disable Bolt or patch immediately.
- Mitigation: Treat any exposed Bolt endpoint as high risk.
- CVE-2026-83947: Azure Event Grid spoofing flaw
- Impact: Event spoofing and workflow abuse.
- Affected Systems: Azure Event Grid.
- Immediate Action: Validate event sources and apply vendor fixes.
- Mitigation: Harden trust boundaries for event ingestion.
- CVE-2026-94664: PDF for Contact Form 7 path traversal
- Impact: Access to restricted files or paths.
- Affected Systems: PDF for Contact Form 7 through 7.1.0.
- Immediate Action: Patch and review file access exposure.
- Mitigation: Restrict filesystem permissions.
- CVE-2026-78025: Dell SCG Policy Manager missing authentication
- Impact: Information disclosure and unauthorized access.
- Affected Systems: SCG Policy Manager before 5.34.00.16.
- Immediate Action: Isolate and patch immediately.
- Mitigation: Restrict remote access until fixed.
- CVE-2026-96336: Forminator authentication bypass
- Impact: Identity spoofing.
- Affected Systems: Forminator through 1.57.2.
- Immediate Action: Update plugin and review account creation flows.
- Mitigation: Require stronger identity checks.
- CVE-2026-96461: Amelia missing authorization
- Impact: Incorrect access control and data exposure.
- Affected Systems: Amelia through 2.4.10.
- Immediate Action: Patch now.
- Mitigation: Recheck role-based permissions.
- CVE-2026-107728: Strawberry GraphQL permission bypass
- Impact: Protected resolvers may run without proper permission checks.
- Affected Systems: Strawberry GraphQL 0.217.0 through 0.326.0.
- Immediate Action: Upgrade to 0.326.1.
- Mitigation: Review custom permission implementations.
- CVE-2026-94666: Generate PDF using Contact Form 7 path traversal
- Impact: Restricted directory access.
- Affected Systems: generate-pdf-using-contact-form-7 through 4.2.1.
- Immediate Action: Patch immediately.
- Mitigation: Lock down file write permissions.
- CVE-2026-96333: GiveWP authentication bypass
- Impact: Identity spoofing and unauthorized access.
- Affected Systems: GiveWP through 4.16.8.1.
- Immediate Action: Update and audit donor/admin access.
- Mitigation: Enforce strong session controls.
- CVE-2026-107911: FalkorDB type confusion in GRAPH.QUERY
- Impact: DoS and possible memory corruption.
- Affected Systems: FalkorDB before 4.20.0, default configs affected.
- Immediate Action: Patch immediately and restrict authenticated query access.
- Mitigation: Monitor for malformed GRAPH.QUERY arguments.
- CVE-2026-76779: Dell SCG excessive authentication attempts flaw
- Impact: Privilege escalation and unauthorized access.
- Affected Systems: SCG Policy Manager before 5.34.00.16.
- Immediate Action: Apply vendor update and lock down remote logins.
- Mitigation: Add rate limits and MFA where possible.
- CVE-2026-81929: Ocean Pro Demos / Ocean eComm Treasure Box stored XSS
- Impact: Script execution in published popups.
- Affected Systems: Ocean Pro Demos up to 1.5.4; Ocean eComm Treasure Box up to 1.8.0.
- Immediate Action: Patch and disable vulnerable popups if needed.
- Mitigation: Sanitize popup content and review published pages.
- CVE-2026-94568: Pay with Vipps for WooCommerce deserialization
- Impact: Object injection and possible RCE.
- Affected Systems: woo-vipps through 6.2.0.
- Immediate Action: Update immediately.
- Mitigation: Audit serialized input handling.
- CVE-2026-95609: Media Library Assistant stored XSS
- Impact: Session hijacking and admin abuse.
- Affected Systems: Media Library Assistant through 3.41.
- Immediate Action: Patch and review media metadata.
- Mitigation: Escape output consistently.
- CVE-2026-78023: Dell SCG authorization bypass via user-controlled key
- Impact: Privilege escalation.
- Affected Systems: SCG Policy Manager before 5.34.00.16.
- Immediate Action: Update and review key-handling logic.
- Mitigation: Restrict remote administrative access.
- CVE-2026-94415: Betheme reflected XSS
- Impact: Script execution in user browsers.
- Affected Systems: Betheme through 28.5.8.
- Immediate Action: Patch and sanitize inputs.
- Mitigation: Deploy output encoding and WAF rules.
- CVE-2026-94668: Salon booking system reflected XSS
- Impact: Browser-side code execution.
- Affected Systems: Salon booking system through 10.31.5.
- Immediate Action: Upgrade immediately.
- Mitigation: Filter user-controlled parameters.
- CVE-2026-95598: Search in Place reflected XSS
- Impact: Session theft and browser compromise.
- Affected Systems: Search in Place through 1.5.5.
- Immediate Action: Patch now.
- Mitigation: Validate all search input.
- CVE-2026-94159: Total Donations stored XSS
- Impact: Persistent script execution.
- Affected Systems: Total Donations through 2.0.5.
- Immediate Action: Update and review donation content fields.
- Mitigation: Sanitize stored content.
- CVE-2026-96553: FiboSearch reflected XSS
- Impact: Browser compromise.
- Affected Systems: ajax-search-for-woocommerce through 1.34.1.
- Immediate Action: Patch and inspect search endpoints.
- Mitigation: Encode output and add CSP.
- CVE-2026-94161: Grand Restaurant reflected XSS
- Impact: Script execution in visitor browsers.
- Affected Systems: Grand Restaurant before 7.0.11.
- Immediate Action: Upgrade immediately.
- Mitigation: Harden template escaping.
- CVE-2026-95591: VikBooking reflected XSS
- Impact: Browser-side code execution.
- Affected Systems: VikBooking through 1.8.14.
- Immediate Action: Patch now.
- Mitigation: Validate all booking fields.
- CVE-2026-95608: HUSKY reflected XSS
- Impact: Session compromise.
- Affected Systems: HUSKY through 1.4.3.2.
- Immediate Action: Update plugin.
- Mitigation: Add output encoding and input validation.
- CVE-2026-96332: Simple Payment reflected XSS
- Impact: Malicious script execution.
- Affected Systems: Simple Payment through 2.5.4.
- Immediate Action: Patch immediately.
- Mitigation: Review payment form parameters.
- CVE-2026-94158: Gloria Admin Panel reflected XSS
- Impact: Admin browser compromise.
- Affected Systems: Gloria Admin Panel through 1.3.
- Immediate Action: Upgrade and restrict admin access.
- Mitigation: Enforce CSP and escaping.
- CVE-2026-94166: UpSolution Core reflected XSS
- Impact: Browser-side code execution.
- Affected Systems: UpSolution Core through 8.44.
- Immediate Action: Patch now.
- Mitigation: Sanitize all rendered content.
- CVE-2026-94632: BlockStrap Page Builder reflected XSS
- Impact: Script execution in visitors’ browsers.
- Affected Systems: BlockStrap Page Builder through 0.1.58.
- Immediate Action: Upgrade immediately.
- Mitigation: Escape block attributes.
- CVE-2026-95596: ShopBuilder reflected XSS
- Impact: Browser compromise.
- Affected Systems: ShopBuilder through 3.4.1.
- Immediate Action: Patch and review storefront widgets.
- Mitigation: Validate all user-supplied fields.
- CVE-2026-96761: Welcart e-Commerce reflected XSS
- Impact: Script execution in browser sessions.
- Affected Systems: Welcart e-Commerce through 2.12.3.
- Immediate Action: Update immediately.
- Mitigation: Apply output encoding.
- CVE-2026-94167: Kubio AI Page Builder reflected XSS
- Impact: Browser compromise.
- Affected Systems: Kubio AI Page Builder through 2.9.3.
- Immediate Action: Patch now.
- Mitigation: Review page-builder inputs.
- CVE-2026-94641: UsersWP reflected XSS
- Impact: Session theft and malicious actions.
- Affected Systems: UsersWP through 1.2.73.
- Immediate Action: Upgrade immediately.
- Mitigation: Sanitize profile fields.
- CVE-2026-94170: Sassy Social Share reflected XSS
- Impact: Client-side code execution.
- Affected Systems: Sassy Social Share through 3.3.79.
- Immediate Action: Patch and test share buttons.
- Mitigation: Use strict escaping.
- CVE-2026-94661: JetBlog reflected XSS
- Impact: Browser compromise.
- Affected Systems: JetBlog through 2.4.10.
- Immediate Action: Update plugin.
- Mitigation: Validate all widget inputs.
- CVE-2026-96607: NEX-Forms reflected XSS
- Impact: Script execution in browser sessions.
- Affected Systems: NEX-Forms through 9.3.1.
- Immediate Action: Patch now.
- Mitigation: Harden form processing.
- CVE-2026-106145: Telerik Report Server service-agent privilege escalation
- Impact: Low-privilege users can register as trusted agents and receive secrets.
- Affected Systems: Telerik Report Server prior to 12.2.26.1007.
- Immediate Action: Upgrade and rotate exposed credentials and keys.
- Mitigation: Audit service-agent registrations immediately.
- CVE-2026-19574: Zephyr ARM64 ASID collision flaw
- Impact: Memory-domain isolation failure and possible kernel compromise.
- Affected Systems: Zephyr ARM64 with userspace and dynamic objects.
- Immediate Action: Patch kernels in production devices now.
- Mitigation: Reduce domain churn and monitor for abnormal memory access.
What to Do Now
- Patch the highest-risk internet-facing systems first: Microsoft cloud services, FalkorDB instances, exposed WordPress plugins, Telerik Report Server, and Zephyr-based embedded devices.
- Disable or isolate risky features until fixed: FalkorDB Bolt, unauthenticated upload endpoints, public admin panels, and any plugin-specific file or popup builders.
- Rotate credentials and secrets if you run Telerik Report Server, Azure services, or any system where privilege escalation or secret disclosure is possible.
- Search for compromise: web shells, unexpected admin accounts, unusual GraphQL or SQL activity, suspicious report objects, and anomalous Bluetooth or Redis traffic.
- Apply compensating controls: WAF rules, network allowlists, MFA, least privilege, and strict admin segmentation.
Verification steps: confirm version numbers against vendor advisories, inventory all exposed instances, and check whether vulnerable plugins or services are actually enabled. For FalkorDB, verify whether Bolt is open; for WordPress, enumerate all installed themes/plugins and remove anything unmaintained.
Monitoring recommendations: alert on new web-accessible files, unexpected outbound callbacks, privilege changes, service-agent registrations, failed-auth spikes, SQL error bursts, and unusual memory or crash patterns in embedded and database services.
Related Resources
- Internal incident-response update: pending publication.
- Internal patch-triage checklist: pending publication.
- Official vendor advisories from Microsoft, FalkorDB, Progress Telerik, Dell, Zephyr Project, and affected WordPress plugin vendors.